In some organisations, risk is a journey; in others, it’s constant. There is no “best practice” risk (or compliance) framework in this context.
Last week, I spoke to a Norwegian firm specialising in constructing and managing renewable energy facilities. Their work is a journey. In this case, across LatAm. The risks differ as the project evolves, for example (very abridged):
🏞️ Land acquisition and clearance: environmental, social, and corruption issues predominate.
👷🏽♀️ Construction: HSE (access, safety, welfare) issues meet, EPC contractors, supply chain transparency (panels, turbines, etc.), human rights, and licensing & permitting challenges.
🔌 Connection to the grid: competition, fraud, corruption, political interference (tariffs, etc.) rise to the top when the project comes on-stream.
🚧 Maintenance: an array of everything above, but a strong emphasis on keeping everyone happy as the workforce downsizes (social risks, fraud, scrap write-off, etc.) and rent-seeking officials (e.g., environmental inspectors) circle.
In this context, the risk framework needs to follow the project. There’s little point in training people to spot misappropriation fraud issues when nothing of value is on-site (pre-land acquisition). Equally, it would be weird to leave your social performance (free, informed, prior consent, etc.) planning for the end of the project.
So far, so intuitive. Well, in theory. In well-run project-led or cyclical firms (construction, energy, agribusiness, etc.), the project leaders live in a world of Gantt charts. Our job is to map our work (both methodologically - prevent, detect, respond) and tactically (see above) to the project. Additionally, there’s (often) an intuitive recognition that not everyone needs to know about every possible risk. This realisation reflects the realities of a highly stratified workforce (engineers to low-literacy labourers).
But what about other industries, where life is more constant?
Enter the avatar. I worked with a marketing and branding team about three years ago to define “customer avatars.” Initially, I hated the concept. Sticking people into clumsy boxes is antithetical to everything I have seen and learned (primarily investigative). It’s the same issue I have with certain HR doctrines, especially the BS cod psychology crud that groups humanity into four colours.
However, the thought experiment of “what are we trying to solve/achieve” is valid. For instance, the business integrity teams within investors are trying to prevent the same things that an in-house counsel at a manufacturing mid-cap might. However, the resources, pressures, stakeholders, remits, workforce composition, workflows, approvals, politics, and more differ.
So, who are the avatars? It depends. So, let’s use an example following the “prevent, detect, respond” framework; we might break down internal avatars as follows:
💡 Prevent: anyone involved in targeting, vetting and selection (customers, strategy, employees, third-parties).
💡 Detect: those onboarding, monitoring, measuring (quality, metrics, targets), or operationalising the strategy.
💡 Respond: support functions (often brought problems), managers, and those executing (sales, transactions, etc.).
If we started assigning names (procurement, operations, business development, etc.) to those categories, we could map relevant risks to their roles. For instance, supply chain transparency requirements might be a high-level “need to know” for staff with sign-off authority but a deep-dive area for procurement. Similarly, anti-competitive practices, gifts, and hospitality don’t apply to those far removed from frontline interactions; they would be highly relevant to strategy setters, executors, and business developers.
I appreciate that much of this is intuitive. However, visually mapping it out (using whiteboards, Venn diagrams, mindmaps, etc.) can help save time (and, therefore, money). Our work (risk management) is facing increased hostility and resentment. We must match project journeys and avatars to maintain relevance and retain allies.
Three years ago, during that marketing work, I was asked to develop Ethics Insight’s “core statement.” It was: “We misunderstand risk and overestimate the effort required to manage it.”
I stand by that. Risk management must shrink to allow us the capacity to manage the ever-expanding list of things it now covers. There’s only one way: make it right-sized and relevant.
Productivity Hacks
You hear a lot about being productive these days. Social media is awash with genuine overachievers and an increasing deluge of charlatans humble-bragging about their morning routines. Sod off.
I’m going to go out on a limb here. Most in-house risk, compliance, and legal professionals I’ve met are biased toward detail and consensus. That’s a terrible mix for work-life balance. You take the time to review everything correctly and then seek to build agreement across disparate viewpoints and incentives. This may explain why I spend more time than I ever imagined having impromptu (or formalised mentoring) chats about career escapes.
But that next job probably won’t help unless we change.
Running this business forced me to change. I physically cannot be across every risk area or evolution. Nor can I consent to every opinion, call on my time, or request. I tried. Two years of 80+ hour weeks and “saying yes to everything until you’re in a position to say no [awful advice]” was unsustainable. Ethics Insight turns six in March 2025. It’s taken me this long to learn the real productivity hacks:
💡 Good questions beat knowledge. 💡 How to say no.
Until this week, I’d never assessed risk and developed an action plan to manage identified issues for a Guatemalan energy facility. If I’d fixated on (lack of) knowledge (my bias), I would not have been able to deliver that project. Instead, I asked better questions (methodology, sector experience, and reading behavioural cues and inconsistencies). The lesson: put the onus on your stakeholders to answer questions they are better placed to address than you rather than trying to solve everything for them.
I received an enquiry from a non-banking financial institution (NBFI) late last week. Their risk framework was in bits (unfit for rapid scaling and misaligned with values and risk realities). The headline risk document exceeded 100 pages. The enquirer requested I review the document and set out a strategy to update, benchmark, align, and gain buy-in from leaders. This “proposal” would be taken to the Board for sign-off. I’d mistakenly been down this path many times - spending days on an unpaid proposal “scope” that either answers enough of the questions or is used as a stalking horse for favoured providers. To overcome this challenge, we developed a low-risk approach, summarised in this document, to properly scope (rightsize) and develop an action plan; the cost is typically about two days of the mean rate for an experienced risk advisor (a steal).
When I explained this approach to the NBFI, crickets. Years ago, I might have panicked. Now I realise we must say no to people who don’t respect or value our time. I appreciate that it’s not always easy. But if you’re in-house, you can create defensible strategies and tools (often ones that require the other party to put some ‘skin in the game’, as I did). Building tested templates that add value but require their input can be an effective way to say “no”.
What repeated time-sucks could you address with templated responses, frameworks, or redirection? And where are you doing the heavy knowledge-lifting for other people? If you want to discuss this, let me know. Helping overburdened people is part of the paying it forward that others did for me when they helped me develop tools like the one mentioned above.
